Guides/Manage your account/Billing/Understand PCI DSS compliance

Understand PCI DSS compliance

Last reviewed on February 12, 2026

This guide explains how PCI DSS applies to WordPress.com sites and what steps you can take as a site owner to help meet compliance requirements.

About PCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed by the Payment Card Industry Security Standards Council (PCI SSC) to protect credit card data during and after transactions. If your site accepts credit card payments, these standards apply to you.

For more information about PCI DSS, review the PCI DSS Quick Reference Guide.

PCI compliance on WordPress.com

The payments infrastructure on WordPress.com—the system we use to process subscription fees and plan purchases—meets PCI DSS requirements.

However, hosting your site on WordPress.com does not automatically make your site PCI compliant.

PCI DSS compliance is assessed per merchant, not per hosting environment. If you accept payments on your site, you are the merchant of record, and your compliance depends on how you implement and manage payments.

Your responsibilities as a site owner

If you accept credit card payments on your WordPress.com site, take these steps to help meet PCI DSS requirements:

Was this guide helpful for you?

Not quite what you're looking for? Get Help!

Copied to clipboard!